GHSA-wrjc-x8rr-h8h6

Suggest an improvement
Source
https://github.com/advisories/GHSA-wrjc-x8rr-h8h6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-wrjc-x8rr-h8h6/GHSA-wrjc-x8rr-h8h6.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-wrjc-x8rr-h8h6
Aliases
Downstream
CGA (21)
MINI (1)
Published
2026-07-23T19:38:28Z
Modified
2026-07-23T19:56:40Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
Details

This is a follow up to CVE-2025-68470. React Router was alerted to certain scenarios in which the fix there was incomplete so there still existed some scenarios where attacker supplied paths passed to navigation mechanisms could result in unexpected external navigations.

Database specific
{
    "cwe_ids":  [
        "CWE-601"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-23T19:38:28Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / react-router

Package

Affected ranges

Type
SEMVER
Events
Introduced
6.0.0
Fixed
7.18.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-wrjc-x8rr-h8h6/GHSA-wrjc-x8rr-h8h6.json"